CrowdStrike Intelligence discovered session histories for "Claude Code," "Claude memory files," and "ARTEX configuration files" while analyzing an infrastructure set up to target South Korean financial institutions.
Infrastructure and timeline of the campaign against South Korean banks
Security researchers identified infrastructure tied to a targeted campaign directed at South Korean financial institutions that was active between late September and early October of this year. The activity was determined to have resulted in exfiltrated data, indicating that the intrusion moved beyond reconnaissance and into successful data theft.
CrowdStrike Intelligence’s artifacts and what they reveal
CrowdStrike Intelligence identified and analyzed the campaign and recovered multiple artifacts that provided direct visibility into the adversary’s operations and tools. Among the items found were session histories for Claude Code, Claude memory files, and ARTEX configuration files. According to the report, these artifacts enabled researchers to observe aspects of the threat actor’s workflows and tool configurations rather than simply infer activity from network telemetry alone.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildAgentic AI tooling paired with conventional offensive capabilities
The threat intelligence described the adversary’s use of agentic AI tooling operating alongside conventional offensive capabilities. The report frames this as part of an observed, evolving trend in adversarial tradecraft: leveraging penetration-testing tools in combination with large language models (LLMs) for attacks. In short, the campaign did not rely solely on traditional malware or exploitation chains; it blended automated, LLM-driven processes with established pentest tooling to carry out the operation.
Attribution: no named actor, provisional language and motive
The activity has not been associated with a named threat actor. CrowdStrike’s research suggests the adversary is Chinese-speaking and financially motivated, but the report stops short of definitive attribution to any identified group. That combination — linguistic indicators plus a clear financial incentive — informed the analysts’ characterization while leaving open formal linkage to previously known actors.
What this means for South Korean banks, security teams, and AI vendors
- South Korean banks: The campaign’s confirmed data exfiltration places banks squarely in the category of affected enterprises; those institutions will need to assess the scope of any data loss tied to the infrastructure CrowdStrike identified and prioritize containment and recovery measures consistent with confirmed breaches.
- Security teams and incident responders: The discovery of session histories, memory files, and configuration artifacts demonstrates that analyst-accessible artifacts can yield rapid insight into adversary methods. Teams should watch for evidence of LLM-assisted workflows combined with pentest tooling in their own telemetry and consider triage processes that surface such artifacts for immediate analysis.
- AI vendors and tooling maintainers: The report highlights a concrete example of agentic AI tooling used in offensive operations. Vendors that produce LLMs, agent frameworks, or penetration-testing platforms will need to evaluate how their tools can be misused in adversarial contexts and consider how telemetry, abuse-detection, and usage policies can help defenders detect anomalous or automated offensive activity.
The facts reported by CrowdStrike show a clear and uncomfortable development: attackers are mixing automated, agentic AI processes with established offensive toolsets to mount financially motivated intrusions, and those intrusions have produced tangible data loss. CrowdStrike’s recovery of session histories and configuration files gives defenders a rare look into the attacker playbook, but it also raises a practical question the reporting leaves open — how many similar campaigns are running below detection thresholds because they do not leave such accessible artifacts? The immediate step is straightforward: affected institutions must confirm scope and containment, and security teams everywhere should elevate detection for LLM-assisted tradecraft paired with pentest tools.




